Legal information
Cookies and Browser Storage
Solarbroom uses only first-party cookies and browser storage that are necessary for sign-in, request security, and remembering the cookie notice.
Session cookie
The session cookie, normally named sb_session, contains a signed reference to the server-side session. It keeps an authorized user signed in and is necessary for access control. It normally expires after 24 hours and is cleared on sign-out. It is protected with Secure, HttpOnly, and SameSite=Lax settings.
Request-security cookie
The sb_csrf cookie contains a random security token used to protect forms and other requests against forgery. It normally expires after 24 hours and is cleared on sign-out. It uses Secure and SameSite=Lax settings and must be readable by the interface for this security purpose.
Cookie-notice storage
The browser storage entry solarbroom_cookie_notice_ack records only that the cookie notice was dismissed and its notice version. It has no fixed expiry and remains until browser storage is cleared or the notice version changes.
Restricted monitoring area
Authorized operators who sign in to the separate, restricted monitoring area receive an additional first-party authentication cookie. Under the current default settings, that session ends after 7 days of inactivity and no later than 30 days after sign-in. The cookie is used only for restricted access and security. The area may also use browser storage for interface preferences, which can be removed through browser settings.
No analytics or marketing cookies
The web-interface does not use analytics, advertising, or cross-site marketing cookies. The items above are necessary for a service requested by the user or for its security, so no optional-cookie consent control is shown.
The service separately creates server-side security and operational records without using analytics cookies. Those records and their purposes are described in the Privacy Policy.
Browser controls
Browser settings can delete or block cookies and local storage. Blocking the session or request-security cookie prevents sign-in or protected actions from working correctly; deleting the notice entry causes the notice to appear again.